From c3d8d3541386580deecfae239c3eef164704b6e1 Mon Sep 17 00:00:00 2001 From: Sayan Chowdhury Date: Fri, 18 Mar 2022 13:21:57 +0530 Subject: [PATCH 1/3] sys-firmware/intel-microcode: Sync with Gentoo upstream gentoo sync ref: https://github.com/gentoo/gentoo/commit/b6146dcdce2f10fd48c070d51ba21e426c5aeaed Signed-off-by: Sayan Chowdhury --- .../coreos-overlay/sys-firmware/intel-microcode/Manifest | 4 ++-- ...10608.ebuild => intel-microcode-20220207_p20220207.ebuild} | 4 ++-- .../coreos-overlay/sys-firmware/intel-microcode/metadata.xml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) rename sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/{intel-microcode-20210608_p20210608.ebuild => intel-microcode-20220207_p20220207.ebuild} (99%) diff --git a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/Manifest b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/Manifest index 932b391f40..e278e13719 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/Manifest +++ b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/Manifest @@ -1,3 +1,3 @@ -DIST intel-microcode-collection-20210608.tar.xz 8012692 BLAKE2B 98df9d18658bfdf06ac7db84ac30707fe8834874583b324ebc882b514975d71b686788fcd1c9b9c5b05448403b27524e29a94ade34facdffb1645333059019a9 SHA512 7fd810cf05334f6442b9a0c77aef5319d3e2006e887d0354dee952647ded3fa6331a30192abf82eda0676af0439b40f5e3ab0210611f96c78fe52f01f106c5d4 +DIST intel-microcode-collection-20220207.tar.xz 9362888 BLAKE2B 9efb2a943bffc1d702675c4ca5d17b6bc7f5bf5688fb1979caadbf96c516c31c3e1894823aaa16dbdb8c778c933eaf49dec6f2d416483d11e58ed1e75823cef8 SHA512 72458aa64c05ceb8bb21b296da5ad15230af3e6ac63240a10370fadec09523cf7ebefaaddce2b31e2c16570c2700a875cccf86fd1770046ff36cc30eb594f041 DIST intel-ucode-sig_0x406e3-rev_0xd6.bin 101376 BLAKE2B 66d55867954d69dda1425febd93bb8c89f7aa836d504f8b5fee127f8505bcf2246f4fcc55cc245bc5e532528d60cca2eee278de7ab5174dc2862db7982a2b36f SHA512 248066b521bf512b5d8e4a8c7e921464ce52169c954d6e4ca580d8c172cd789519e22b4cf56c212e452b4191741f0202019f7061d322c9433b5af9ce5413b567 -DIST microcode-20210608.tar.gz 4782451 BLAKE2B 2eac43aaa7832365e428bf2de20797ef42293a53087545920d205bd3b11a3d8ca2afb33931af5d36b8f3a224b9c22ed89ff828acc8afdcfa1b8220884c55ae89 SHA512 61acd2e76aa019fa0002fbf56c503791080a937ff93d81e020f8f0cc089dc08928b4c7e9884f713b886e2f9d4a8409fea59e39f628ef534a588515e1c3fc861d +DIST microcode-20220207.tar.gz 4590237 BLAKE2B 8c47a330794615b6684084976b6bb9e8800cd2869f81ecc33b28b54441b220a645502c0ade0cbd58e91879a652ff6bca181800004de477fc74033413ea4b1c8f SHA512 efa9f80815947cf2be371e7da7185634cbacefe779d1d6dfef0c15b78ccae7d2740ea6681b967a19dfbcc3014edce5bcdcdba87c9dea1f19d0415a03fca9e936 diff --git a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20210608_p20210608.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild similarity index 99% rename from sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20210608_p20210608.ebuild rename to sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild index 7da8ed41d1..adfb7ec7e6 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20210608_p20210608.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild @@ -1,4 +1,4 @@ -# Copyright 1999-2021 Gentoo Authors +# Copyright 1999-2022 Gentoo Authors # Distributed under the terms of the GNU General Public License v2 EAPI="7" @@ -20,7 +20,7 @@ SRC_URI="https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/arc https://dev.gentoo.org/~whissi/dist/intel-microcode/intel-microcode-collection-${COLLECTION_SNAPSHOT}.tar.xz" LICENSE="intel-ucode" -SLOT="0/${PVR}" +SLOT="0" KEYWORDS="-* amd64 x86" IUSE="hostonly initramfs +split-ucode vanilla" REQUIRED_USE="|| ( initramfs split-ucode )" diff --git a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/metadata.xml b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/metadata.xml index 6613dbb47e..d12b8b0925 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/metadata.xml +++ b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/metadata.xml @@ -1,5 +1,5 @@ - + base-system@gentoo.org From 052c968ac867e56990fb0cf400c4e5b9f7acc641 Mon Sep 17 00:00:00 2001 From: Sayan Chowdhury Date: Fri, 18 Mar 2022 13:24:24 +0530 Subject: [PATCH 2/3] sys-firmware/intel-microcode: Apply Flatcar patches Signed-off-by: Sayan Chowdhury --- .../intel-microcode/intel-microcode-20220207_p20220207.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild index adfb7ec7e6..ddbed3f950 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/sys-firmware/intel-microcode/intel-microcode-20220207_p20220207.ebuild @@ -20,7 +20,7 @@ SRC_URI="https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/arc https://dev.gentoo.org/~whissi/dist/intel-microcode/intel-microcode-collection-${COLLECTION_SNAPSHOT}.tar.xz" LICENSE="intel-ucode" -SLOT="0" +SLOT="0/${PVR}" KEYWORDS="-* amd64 x86" IUSE="hostonly initramfs +split-ucode vanilla" REQUIRED_USE="|| ( initramfs split-ucode )" From dce35b0a126a2f7308cc873fbac2723a8dd7e586 Mon Sep 17 00:00:00 2001 From: Sayan Chowdhury Date: Fri, 18 Mar 2022 13:35:25 +0530 Subject: [PATCH 3/3] sys-firware/intel-microcode: Add the changelog entries for 20220207_p20220207 Signed-off-by: Sayan Chowdhury --- .../security/2022-03-18-intel-microcode-20220207_p20220207.md | 1 + .../updates/2022-03-18-intel-microcode-20220207_p20220207.md | 1 + 2 files changed, 2 insertions(+) create mode 100644 sdk_container/src/third_party/coreos-overlay/changelog/security/2022-03-18-intel-microcode-20220207_p20220207.md create mode 100644 sdk_container/src/third_party/coreos-overlay/changelog/updates/2022-03-18-intel-microcode-20220207_p20220207.md diff --git a/sdk_container/src/third_party/coreos-overlay/changelog/security/2022-03-18-intel-microcode-20220207_p20220207.md b/sdk_container/src/third_party/coreos-overlay/changelog/security/2022-03-18-intel-microcode-20220207_p20220207.md new file mode 100644 index 0000000000..6a07feedc4 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/changelog/security/2022-03-18-intel-microcode-20220207_p20220207.md @@ -0,0 +1 @@ +- intel-microcode ([CVE-2021-0127](https://nvd.nist.gov/vuln/detail/CVE-2021-0127), [CVE-2021-0146](https://nvd.nist.gov/vuln/detail/CVE-2021-0146)) diff --git a/sdk_container/src/third_party/coreos-overlay/changelog/updates/2022-03-18-intel-microcode-20220207_p20220207.md b/sdk_container/src/third_party/coreos-overlay/changelog/updates/2022-03-18-intel-microcode-20220207_p20220207.md new file mode 100644 index 0000000000..0fb5344071 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/changelog/updates/2022-03-18-intel-microcode-20220207_p20220207.md @@ -0,0 +1 @@ +- intel-microcode ([20220207_p20220207](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220207)